bybit-trading
Warn
Audited by Socket on Aug 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the trading purpose aligns with Bybit API access and credential use, and data flows stay mostly within official Bybit/GitHub-owned infrastructure. However, the skill has elevated risk because it self-updates from remote mutable content, lazy-fetches code/modules, and authorizes autonomous high-impact financial actions; this is coherent with purpose but not low-risk.
Confidence: 89%Severity: 74%
Audit Metadata